• News/
  • https://www.theregister.com/2024/01/16/more_than_178000_sonicwall_firewalls/

178,000 SonicWall firewalls are vulnerable to old DoS bugs

The Register
·
Connor Jones
·
Published Jan 16, 2024
·
Updated

Updated More than 178,000 SonicWall firewalls are still vulnerable to years-old vulnerabilities, an infosec reseacher claims. A study by Jon Williams, senior security engineer at Bishop Fox, this week highlights what he refers to as weapons-grade patch apathy from SonicWall customers, with the number of exploitable devices representing 76 percent of those that are public-facing. With a focus on CVE-2022-22274 and CVE-2023-0656 specifically, Williams said 178,637 of 233,984 public-facing SonicWall next-generation firewall (NGFW) series 6 and 7 devices are vulnerable to one or both of these flaws. Both vulnerabilities lead to denial of service (DoS), but the former is easily the most serious since it can also potentially lead to remote code execution (RCE), earning it a near-maximum 9.8 severity score for its exploitability and potential impact. "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern," said Williams. SSD Labs previously stated that in both cases, cybercrims are “tasked with exploiting a stack overflow vulnerability to cause the DoS - remotely carried out by sending a malicious HTTP request. “The specific flaw exists within the httpServer function,” it added. “The issue results from the lack of checking the return result of snprintf before using it to calculate the maximum length. An attacker can leverage this vulnerability to impact the availability of the target se...

Read full article

Affected Software

2 affected components
SonicWall next-generation firewall (NGFW)=series 6
SonicWall next-generation firewall (NGFW)=series 7
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the vulnerability of over 178,000 SonicWall firewalls to outdated denial-of-service (DoS) bugs.

2

What security implications are discussed in the article?

The vulnerabilities expose SonicWall firewalls to potential exploitation that can lead to denial of service attacks.

3

What products or software are affected by these vulnerabilities?

The affected products include SonicWall next-generation firewalls (NGFW) in series 6 and series 7.

4

Who conducted the study highlighting these vulnerabilities?

The study was conducted by Jon Williams, a senior security engineer at Bishop Fox.

5

How long have these vulnerabilities been present in SonicWall firewalls?

The vulnerabilities have existed for several years, making the situation particularly concerning.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203